Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

1,308 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2021-27877 Veritas Backup Exec Agent Veritas Backup Exec Agent Improper Authentication Vulnerability 85 Immediate 0.649 (99.19th pctl) Known 2023-04-28
CVE-2021-27104 Accellion FTA Accellion FTA OS Command Injection Vulnerability 85 Immediate 0.564 (99th pctl) Known 2021-11-17
CVE-2022-29499 Mitel MiVoice Connect Mitel MiVoice Connect Data Validation Vulnerability 85 Immediate 0.556 (99th pctl) Known 2022-07-18
CVE-2021-22941 Citrix ShareFile Citrix ShareFile Improper Access Control Vulnerability 85 Immediate 0.536 (98.9th pctl) Known 2022-04-15
CVE-2020-12812 Fortinet FortiOS Fortinet FortiOS SSL VPN Improper Authentication Vulnerability 85 Immediate 0.493 (98.8th pctl) Known 2022-05-03
CVE-2021-22893 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Use-After-Free Vulnerability 85 Immediate 0.472 (98.8th pctl) Known 2022-05-03
CVE-2020-12271 Sophos SFOS Sophos SFOS SQL Injection Vulnerability 85 Immediate 0.424 (98.6th pctl) Known 2022-05-03
CVE-2026-12569 PTC Windchill and FlexPLM PTC Windchill and FlexPLM Improper Input Validation Vulnerability 85 Immediate 0.406 (98.6th pctl) Known 2026-06-28
CVE-2021-20016 SonicWall SSLVPN SMA100 SonicWall SSLVPN SMA100 SQL Injection Vulnerability 85 Immediate 0.400 (98.5th pctl) Known 2021-11-17
CVE-2022-31199 Netwrix Auditor Netwrix Auditor Insecure Object Deserialization Vulnerability 85 Immediate 0.360 (98.4th pctl) Known 2023-08-01
CVE-2026-20131 Cisco Secure Firewall Management Center (FMC) Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability 85 Immediate 0.312 (98.1st pctl) Known 2026-03-22
CVE-2021-20028 SonicWall Secure Remote Access (SRA) SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability 85 Immediate 0.299 (98.1st pctl) Known 2022-04-18
CVE-2018-20753 Kaseya Virtual System/Server Administrator (VSA) Kaseya VSA Remote Code Execution Vulnerability 85 Immediate 0.293 (98th pctl) Known 2022-05-04
CVE-2020-5135 SonicWall SonicOS SonicWall SonicOS Buffer Overflow Vulnerability 85 Immediate 0.269 (97.9th pctl) Known 2022-04-05
CVE-2023-20269 Cisco Adaptive Security Appliance and Firepower Threat Defense Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability 85 Immediate 0.254 (97.8th pctl) Known 2023-10-04
CVE-2023-48365 Qlik Sense Qlik Sense HTTP Tunneling Vulnerability 85 Immediate 0.247 (97.7th pctl) Known 2025-02-03
CVE-2018-19949 QNAP Network Attached Storage (NAS) QNAP NAS File Station Command Injection Vulnerability 85 Immediate 0.244 (97.7th pctl) Known 2022-06-14
CVE-2025-23006 SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances Deserialization Vulnerability 85 Immediate 0.234 (97.6th pctl) Known 2025-02-14
CVE-2024-9680 Mozilla Firefox Mozilla Firefox Use-After-Free Vulnerability 85 Immediate 0.232 (97.6th pctl) Known 2024-11-05
CVE-2016-1019 Adobe Flash Player Adobe Flash Player Arbitrary Code Execution Vulnerability 85 Immediate 0.225 (97.5th pctl) Known 2022-03-24
CVE-2024-40766 SonicWall SonicOS SonicWall SonicOS Improper Access Control Vulnerability 85 Immediate 0.182 (97th pctl) Known 2024-09-30
CVE-2019-7193 QNAP QTS QNAP QTS Improper Input Validation Vulnerability 85 Immediate 0.144 (96.4th pctl) Known 2022-06-22
CVE-2025-42999 SAP NetWeaver SAP NetWeaver Deserialization Vulnerability 85 Immediate 0.139 (96.3rd pctl) Known 2025-06-05
CVE-2026-9586 Sangoma Switchvox Sangoma Switchvox SQL Injection Vulnerability 85 Immediate 0.118 (95.8th pctl) Unknown/None 2026-09-05
CVE-2012-1710 Oracle Fusion Middleware Oracle Fusion Middleware Unspecified Vulnerability 85 Immediate 0.116 (95.8th pctl) Known 2022-06-15
Download filtered advisories (CSV)

Exactly the 1,308 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2021-27877 — Veritas Backup Exec Agent: Veritas Backup Exec Agent Improper Authentication Vulnerability

Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.649 (99.19th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-04-07

CISA remediation due: 2023-04-28

Known ransomware campaign use: Known

CVE-2021-27104 — Accellion FTA: Accellion FTA OS Command Injection Vulnerability

Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.564 (99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Known

CVE-2022-29499 — Mitel MiVoice Connect: Mitel MiVoice Connect Data Validation Vulnerability

The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.556 (99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-27

CISA remediation due: 2022-07-18

Known ransomware campaign use: Known

CVE-2021-22941 — Citrix ShareFile: Citrix ShareFile Improper Access Control Vulnerability

Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.536 (98.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-25

CISA remediation due: 2022-04-15

Known ransomware campaign use: Known

CVE-2020-12812 — Fortinet FortiOS: Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.493 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Known

CVE-2021-22893 — Ivanti Pulse Connect Secure: Ivanti Pulse Connect Secure Use-After-Free Vulnerability

Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.472 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Known

CVE-2020-12271 — Sophos SFOS: Sophos SFOS SQL Injection Vulnerability

Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.424 (98.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Known

CVE-2026-12569 — PTC Windchill and FlexPLM: PTC Windchill and FlexPLM Improper Input Validation Vulnerability

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 9.3 (NVD)

FIRST EPSS: 0.406 (98.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-06-25

CISA remediation due: 2026-06-28

Known ransomware campaign use: Known

CVE-2021-20016 — SonicWall SSLVPN SMA100: SonicWall SSLVPN SMA100 SQL Injection Vulnerability

SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.400 (98.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2021-11-17

Known ransomware campaign use: Known

CVE-2022-31199 — Netwrix Auditor: Netwrix Auditor Insecure Object Deserialization Vulnerability

Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.360 (98.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-07-11

CISA remediation due: 2023-08-01

Known ransomware campaign use: Known

CVE-2026-20131 — Cisco Secure Firewall Management Center (FMC): Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.312 (98.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-03-19

CISA remediation due: 2026-03-22

Known ransomware campaign use: Known

CVE-2021-20028 — SonicWall Secure Remote Access (SRA): SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.299 (98.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-28

CISA remediation due: 2022-04-18

Known ransomware campaign use: Known

CVE-2018-20753 — Kaseya Virtual System/Server Administrator (VSA): Kaseya VSA Remote Code Execution Vulnerability

Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.293 (98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-04-13

CISA remediation due: 2022-05-04

Known ransomware campaign use: Known

CVE-2020-5135 — SonicWall SonicOS: SonicWall SonicOS Buffer Overflow Vulnerability

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.269 (97.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-15

CISA remediation due: 2022-04-05

Known ransomware campaign use: Known

CVE-2023-20269 — Cisco Adaptive Security Appliance and Firepower Threat Defense: Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions for group-lock and vpn-simultaneous-logins or discontinue use of the product for unsupported devices.

CVSS: 9.1 (NVD)

FIRST EPSS: 0.254 (97.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-09-13

CISA remediation due: 2023-10-04

Known ransomware campaign use: Known

CVE-2023-48365 — Qlik Sense: Qlik Sense HTTP Tunneling Vulnerability

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.9 (NVD)

FIRST EPSS: 0.247 (97.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-01-13

CISA remediation due: 2025-02-03

Known ransomware campaign use: Known

CVE-2018-19949 — QNAP Network Attached Storage (NAS): QNAP NAS File Station Command Injection Vulnerability

A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.244 (97.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-24

CISA remediation due: 2022-06-14

Known ransomware campaign use: Known

CVE-2025-23006 — SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances Deserialization Vulnerability

SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.234 (97.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-01-24

CISA remediation due: 2025-02-14

Known ransomware campaign use: Known

CVE-2024-9680 — Mozilla Firefox: Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.232 (97.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-10-15

CISA remediation due: 2024-11-05

Known ransomware campaign use: Known

CVE-2016-1019 — Adobe Flash Player: Adobe Flash Player Arbitrary Code Execution Vulnerability

Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: The impacted product is end-of-life and should be disconnected if still in use.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.225 (97.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Known

CVE-2024-40766 — SonicWall SonicOS: SonicWall SonicOS Improper Access Control Vulnerability

SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.182 (97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-09-09

CISA remediation due: 2024-09-30

Known ransomware campaign use: Known

CVE-2019-7193 — QNAP QTS: QNAP QTS Improper Input Validation Vulnerability

QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.144 (96.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-06-08

CISA remediation due: 2022-06-22

Known ransomware campaign use: Known

CVE-2025-42999 — SAP NetWeaver: SAP NetWeaver Deserialization Vulnerability

SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.1 (NVD)

FIRST EPSS: 0.139 (96.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-05-15

CISA remediation due: 2025-06-05

Known ransomware campaign use: Known

CVE-2026-9586 — Sangoma Switchvox: Sangoma Switchvox SQL Injection Vulnerability

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 9.3 (NVD)

FIRST EPSS: 0.118 (95.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-09-02

CISA remediation due: 2026-09-05

Known ransomware campaign use: Unknown/None

CVE-2012-1710 — Oracle Fusion Middleware: Oracle Fusion Middleware Unspecified Vulnerability

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.116 (95.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-25

CISA remediation due: 2022-06-15

Known ransomware campaign use: Known

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.